Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-30624: Remote code execution in Agent Zero MCP server configuration

Agent Zero 0.9.8 allows users to define External MCP Servers via JSON configuration with arbitrary command and args values that are executed without sufficient validation. A malicious MCP configuration can therefore run arbitrary operating system commands with the privileges of the Agent Zero process.

Disclosed 15 April 2026 · Record updated 13 September 2026

Impact

Attacker-supplied MCP server configuration can lead to remote code execution with the privileges of the Agent Zero process.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-30624